CVE-2017-17083: High severity Wireshark Wireshark vulnerability
Published Dec 1, 2017
·Updated
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash. This was addressed in epan/dissectors/packet-netbios.c by ensuring that write operations are bounded by the beginning of a buffer.
Affected Software
17 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark=2.2.0
Wireshark Wireshark=2.2.1
Wireshark Wireshark=2.2.2
Wireshark Wireshark=2.2.3
Wireshark Wireshark=2.2.4
Wireshark Wireshark=2.2.5
Wireshark Wireshark=2.2.6
Wireshark Wireshark=2.2.7
Wireshark Wireshark=2.2.8
Wireshark Wireshark=2.2.9
Wireshark Wireshark=2.2.10
Wireshark Wireshark=2.4.0
Wireshark Wireshark=2.4.1
Wireshark Wireshark=2.4.2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Dec 1, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17083?
CVE-2017-17083 is considered a medium severity vulnerability that can cause crashes in the Wireshark application.
2
How do I fix CVE-2017-17083?
To fix CVE-2017-17083, update Wireshark to version 2.4.3 or later, or any of the patched versions listed in the advisory.
3
Which versions of Wireshark are affected by CVE-2017-17083?
Versions of Wireshark from 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10 are affected by CVE-2017-17083.
4
What component of Wireshark is impacted by CVE-2017-17083?
The NetBIOS dissector component of Wireshark is impacted by CVE-2017-17083.
5
Is it safe to use Wireshark with CVE-2017-17083 present?
Using an affected version of Wireshark can lead to application crashes, making it unsafe to use until remediated.